Privacy policy

This policy describes the independent, owner-operated Hermes Google Drive backup integration.

Information accessed

Purpose and limited use

Information is used only to provide the owner's backup transfer, integrity verification, restoration and authorized cleanup functions. It is not sold, used for advertising, used for credit decisions, or used to train general-purpose AI models.

Hermes's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Storage and security

Backup objects are stored in the owner's Google Drive. Local working files, verification records and credentials are stored on an owner-controlled server. The configured Windows implementation protects OAuth credentials with user-bound Windows DPAPI and restricted file permissions. Private backup archives must be encrypted before upload, with independently retained recovery material. This informational website does not host backups, OAuth credentials or encryption keys.

Service providers and automation

Google processes authorized API requests and stores Drive objects. The server operator and the operator's infrastructure providers process data needed to run the backup integration. The operator may use automation assistants for setup and diagnostics; diagnostic output must exclude OAuth secrets and private archive contents and must be limited to necessary operational metadata.

This public website is hosted by Cloudflare. Cloudflare may process standard network and security information such as IP addresses, request paths and timestamps under its privacy policy. This site contains no application login form, advertising, third-party analytics scripts or intentional application tracking cookies.

Retention, revocation and deletion

Archive retention is controlled by the owner. Test objects may be deleted after verified roundtrips. No automatic deletion of source backups is implied by connecting the application. Local operational records are retained until the operator removes them.

The owner can revoke access in Google Account connections, remove stored credentials from the server, and delete application-created Drive objects through Google Drive. Revoking access does not itself delete previously stored files or local copies. Provider retention and trash behavior remain subject to the provider's policies.

Contact and updates

For access, correction or deletion questions, contact the account owner/operator using the support email shown on the Google consent screen. This is a private integration rather than a publicly offered user-account service. Material changes to data handling must be reflected in this policy before they are adopted.